Splunk Search

Splunk Search
Community Activity
pramodkumar
Hi, What specifically the tail -f option do, in which scenario it works perfect. Please any example would be great..
by pramodkumar Path Finder in Splunk Search 01-05-2013
0 4
0
4
mikeely
Am trying to index web logs from an intranet site, so I did the setup for Web Intelligence as follows: sourcetype...
by mikeely Path Finder in Splunk Search 01-05-2013
2 8
2
8
mhale1982
I'm having some issues with using regex to define the host of some events from an ASA. The events are in the format ...
by mhale1982 Path Finder in Splunk Search 01-04-2013
1 8
1
8
Dimitri_McKay
It does not appear that there's any way to do host templating. We have 1000s of servers, many of which are based off...
by Dimitri_McKay Splunk Employee Splunk Employee in Splunk Search 01-04-2013
0 2
0
2
falkyre
Still trying to get the tail monitor working. It seems that once it's enabled and scheduled, then executed, the firs...
by falkyre Explorer in Splunk Search 01-04-2013
1 1
1
1
Dimitri_McKay
Does the charting data "age" like RRD data (as an example: a 5 minute sample rate gets turned into a 15 minute averag...
by Dimitri_McKay Splunk Employee Splunk Employee in Splunk Search 01-04-2013
0 1
0
1
DaClyde
Is there any way to tack labels, like units of measure, onto values in a table of results, similar to how it can be d...
by DaClyde Contributor in Splunk Search 01-04-2013
0 3
0
3
dianbo_1
Hi, I want to create a dashboard with 4 tables. I used a hidden search with 4 hiddenpostprocess(s). But all 4 tables...
by dianbo_1 Path Finder in Splunk Search 01-04-2013
2 5
2
5
DerekB
We upgraded from 4.2 to 4.3.5 because we had a sources.data that was many GB in size. To resolve this, we tried to up...
by DerekB Splunk Employee Splunk Employee in Splunk Search 01-04-2013
9 1
9
1
ugillr
I am sending CSV files to my Splunk machine. These files vary in record count from 1 to 5000. When I search for all o...
by ugillr Engager in Splunk Search 01-04-2013
0 12
0
12
asarolkar
I have a question about constants and timechart/chart/stats I have a search like this sourcetype="syslog" | ... | e...
by asarolkar Builder in Splunk Search 01-04-2013
0 3
0
3
username9000
Greetings, I am trying to output an IP address from a search to a script. My goal is to have the search call a scrip...
by username9000 New Member in Splunk Search 01-04-2013
0 4
0
4
itghelp
I'm trying to get Splunk to properly break multi-line events from Radiator radius server using BREAK_ONLY_BEFORE_DATE...
by itghelp Path Finder in Splunk Search 01-04-2013
0 4
0
4
tb5821
A have a ...| selfjoin subsearch which joins on two fields id, vid. I then pass the fields I want kept to my main se...
by tb5821 Communicator in Splunk Search 01-04-2013
0 6
0
6
arockiam
Hello I am forwarding remote Linux machines' logs to central splunk; and doing the simple GUI search as below: source...
by arockiam New Member in Splunk Search 01-04-2013
0 3
0
3
jpn627
Hi all: Is there an easy way to put a download link in a table? I've got a dashboard with IDS events, and I need to ...
by jpn627 New Member in Splunk Search 01-04-2013
0 1
0
1
infyravi
Hi, I am having 2 log files like this 1) abc.log 2) master.log In the master.log I am having master data like UR...
by infyravi Explorer in Splunk Search 01-03-2013
2 3
2
3
jericksonpf
Hi, I am using a query that uses the awesome percentage value feature built into stats. It outputs into a table that...
by jericksonpf Path Finder in Splunk Search 01-03-2013
0 5
0
5
asarolkar
I have a search like this sourcetype="syslog" | ... | stats c(eval(range="alpha")) AS ALPHA_COUNT c(eval(range="beta...
by asarolkar Builder in Splunk Search 01-03-2013
0 3
0
3
asarolkar
I have a search which gives me a whole range of timestamps (the usual date _ hour, date _ minute and date_second) I ...
by asarolkar Builder in Splunk Search 01-03-2013
0 5
0
5
Michael_Schyma1
Is there a way to combine two stanzas in transforms in order to block events. in this case specific event codes and...
by Michael_Schyma1 Contributor in Splunk Search 01-03-2013
1 1
1
1
jedatt01
I have an input that's value is like an odometer so it's cumulative. I collect a sample every five minutes. If I want...
by jedatt01 Builder in Splunk Search 01-03-2013
0 1
0
1
robK123
I have a single value search that I have added to my dashboard I want it to change colour and have added this to the ...
by robK123 Explorer in Splunk Search 01-03-2013
0 4
0
4
mchang_splunk
After upgrading to 5.0, I find the default value of max_searches_per_cpu and base_max_searches in /etc/system/default...
by mchang_splunk Splunk Employee Splunk Employee in Splunk Search 01-03-2013
9 1
9
1
samsplunkd
Hi, I am planning to implement exponential smoothing in Splunk based on below formula where s1 is the forecasted va...
by samsplunkd Path Finder in Splunk Search 01-03-2013
0 3
0
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...